Listing Thumbnail

    CIS Hardened Image Level 1 on Microsoft Windows Server 2019

     Info
    Deployed on AWS
    AWS Free Tier
    This product has charges associated with the pre-built hardening to the CIS Benchmarks™ and recurring maintenance. The CIS Hardened Images® are hardened in accordance with the associated CIS Benchmarks, an industry best practice for secure configuration. Reduce cost, time, and risk by building your AWS solution with CIS AMIs.

    Overview

    The CIS Hardened Image Level 1 on Microsoft Windows Server 2019 is a pre-configured image built by the Center for Internet Security (CIS®) for use on Amazon Elastic Compute Cloud (Amazon EC2). It is a pre-configured, security-hardened image that aligns with the robust security recommendations, the CIS Benchmarks, making it easier for organizations to meet regulatory requirements.

    Not only is this image pre-hardened to the CIS Benchmarks guidance, but it is also patched monthly in alignment with the updates from the software vendor.

    Key Benefits

  • Enhanced Security: Mitigates risks like malware, denial of service, and authorization issues by following globally-recognized secure configuration guidance to support your cloud security posture management (CSPM) program.
  • Compliance Readiness: Helps your organization comply with PCI DSS, FedRAMP, DoD Cloud Computing SRG, FISMA, select NIST publications, and more.
  • Faster Deployment: Pre-configured according to CIS Benchmarks, allowing you to deploy secure virtual machine images.
  • Consistency Across Environments: Ensures consistent security configurations across development, testing, and production environments, reducing drift and compatibility risks.
  • Cost Efficiency: Lowers remediation efforts, reduces attack surface, and minimizes business loss from security incidents.
  • Easier Maintenance: Regular updates ensure that your systems are always in line with the latest security standards and software patches.

    This image is hardened against the corresponding Level 1 profile which is intended to be practical and prudent, provide a clear security benefit, and not inhibit the utility of the technology beyond acceptable means. No components are installed on or removed from this image outside of those already present on the base image or as recommended in alignment with the corresponding CIS Benchmark recommendations.

    To demonstrate conformance to the CIS Microsoft Windows Server 2019 Level 1 Benchmark, industry-recognized hardening guidance, each image includes an HTML report from CIS Configuration Assessment Tool (CIS-CAT® Pro). Each CIS Hardened Image contains the following files:

  • Base_CIS-CAT_Report.html - this provides a report of CIS-CAT Pro run against the instance before any change is made by CIS (e.g., software updates, CIS hardening).
  • CIS-CAT_Report.html - this provides a report of CIS-CAT Pro run against the instance after the corresponding CIS Benchmark was applied to the image.
  • Exceptions.txt - this provides a list of recommendations that are not applied because the configuration of those recommendations may inhibit the use of this image in this CSP, require environment-specific expertise, or hinder the integration of this image with CSP services or extensions.

    These reports are located in C:\CIS Hardening Reports.

    If this instance is used in a domain environment where policies are managed globally, the majority of the security settings will be changed and managed by domain policies.

    For customized pricing options or private offers, reach out to us at cloudsecurity@cisecurity.org .

    To learn more or access the corresponding CIS Benchmark, please visit https://www.cisecurity.org/cis-benchmarks  or sign up for a free account on our community platform, CIS WorkBench, https://workbench.cisecurity.org/ .

  • Highlights

    • Hardened according to a Level 1 CIS Benchmark that is developed in a consensus-based process and that is accepted by government, business, industry, and academia.
    • Helps with compliance to PCI DSS, FedRAMP, DoD Cloud Computing SRG, FISMA, select NIST publications, and more.
    • Pre-configured to align with industry best practices that are developed and supported by CIS, this image has hardened account and local policies, firewall configuration, and computer-based and user-based administrative templates.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Win2019 10.0.17763

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    CIS Hardened Image Level 1 on Microsoft Windows Server 2019

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (630)

     Info
    • ...
    Dimension
    Cost/hour
    t2.large
    Recommended
    $0.022
    t2.micro
    AWS Free Tier
    $0.02
    t3.micro
    AWS Free Tier
    $0.022
    m6a.32xlarge
    $0.06
    g2.8xlarge
    $0.05
    gr6.8xlarge
    $0.05
    c6in.32xlarge
    $0.06
    r5a.16xlarge
    $0.06
    m5a.xlarge
    $0.024
    r6a.48xlarge
    $0.06

    Vendor refund policy

    Refunds through AWS are not available at this time. You will only be billed for actual time of instance use. As with all CIS security products, our aim is always 100 percent customer/member satisfaction.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    NA

    Additional details

    Usage instructions

    Once the instance is running, choose Get Windows Password in the EC2 console then connect using a Remote Desktop Connection (RDP) client. The RDP client MUST be able to authenticate using NTLMv2. Immediately apply latest security updates after launching the instance.

    Support

    Vendor support

    Questions, feedback, and support accessing CIS-developed AMIs is provided by contacting

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Operating Systems, Security

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    4 reviews
    Insufficient data
    Insufficient data
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Security Configuration
    Pre-hardened image aligned with CIS Benchmarks Level 1 security recommendations
    Compliance Reporting
    Includes CIS Configuration Assessment Tool (CIS-CAT Pro) HTML reports for security conformance verification
    Hardening Scope
    Implements hardened account policies, local policies, firewall configurations, and administrative templates
    Patch Management
    Monthly software updates synchronized with vendor patch release cycles
    Security Assessment
    Provides detailed exception tracking and pre/post hardening configuration reports
    Cryptographic Compliance
    FIPS 140-2 certified kernel and cryptographic modules with out-of-the-box compliance
    Security Patch Coverage
    Comprehensive security updates for over 23,000 open source packages across Ubuntu Universe repository
    Compliance Hardening
    Integrated hardening profiles from CIS and DISA-STIG security implementation guidelines
    Kernel Security
    FIPS-certified kernel with ongoing security updates for cryptographic components
    Security Tooling
    Ubuntu Security Guide (USG) for automated compliance and security configuration management
    Security Configuration
    Pre-configured security safeguards with minimized attack surfaces and default protective measures
    Compliance Framework
    Vendor-neutral security configuration aligned with multiple cybersecurity compliance standards
    System Optimization
    Preconfigured Linux system tailored for system administrators, security experts, and platform deployment professionals
    Security Standard Adherence
    Image developed through consensus-based approach following industry-recognized security benchmarks

    Contract

     Info
    Standard contract
    No

    Customer reviews

    Ratings and reviews

     Info
    4
    2 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    100%
    0%
    0%
    0%
    2 AWS reviews
    |
    40 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    AndreyKolmakov

    Windows Server boosts file sharing efficiency and simplifies permission management

    Reviewed on Jun 17, 2025
    Review from a verified AWS customer

    What is our primary use case?

    The main use cases for Windows Server  involve file sharing, such as file server and network shares. We are not a big organization using Windows Server . We are in the transportation industry, and we have a data center. We have approximately 15 servers and 50 machines, some of them are virtual.

    How has it helped my organization?

    The Active Directory integration helps my organization manage permissions and maintain security policies effectively. The security groups are perfect for what I need. I can give groups of users access to specific subfolders easily through the AD security group instead of adding users individually. You simply add them to a security group and the rest of it follows. This is a good mechanism.

    It definitely saves my team a lot of time. It's hard to say exactly how much time it saves, but imagine you need to add five new users to a share. Instead of going in, logging in, and finding the user, I just add the members to the group. Click okay, apply, and they have access to the network shares. I don't even need to access the server directly, which is a nice part of it.

    What is most valuable?

    The best features of Windows Server are that it works and gives us everything we need to share files and set security permissions. It is done effectively in terms of the NTFS permissions. I can base them on AD security groups.

    I have utilized the Active Directory integration in Windows Server for identity management, and they are on a domain.

    What needs improvement?

    We haven't utilized Windows containers and Kubernetes  for deploying any applications. I'm trying to learn it and have started to watch YouTube content for my understanding.

    I cannot tell if the security enhancements such as Windows Defender Advanced Threat Protection have contributed to protecting sensitive data.

    We have not implemented the failover clustering feature in Windows Server.

    For how long have I used the solution?

    I have experience with Windows Server for approximately four to five years.

    What do I think about the stability of the solution?

    In terms of stability, I would say it's good. Looking at Windows Server 2025, there are still bugs to fix, but 2019 has been there for years and is pretty stable. It's doing a very good job.

    What do I think about the scalability of the solution?

    I think Windows Server does a very good job with scalability. From what I've read, it can scale out easily.

    How are customer service and support?

    I have not dealt with Microsoft customer service or technical support directly. My colleague worked with them, and they were available and helped fix the issue. It worked.

    How would you rate customer service and support?

    Which solution did I use previously and why did I switch?

    I assess the impact of Hyper-V  technology on our resource utilization and hardware costs as very attractive after Broadcom killed VMware for small companies. That's why I'm looking at other technologies and what people say about them.

    How was the initial setup?

    The initial setup of Windows Server is straightforward in my opinion. It comes with lots of features or things by default. It's already set up with a certain level of security and other things that require hardening based on our company policies, but it's straightforward. It's doing its job and comes ready to continue the setup.

    What other advice do I have?

    I do not have experience with Azure  products or Citrix. I'm getting to know what other people are saying about the product.

    I do not deal with any other types of products such as Cisco, Fortinet, Palo Alto, or testing tools. I just work with Windows Server.

    I do not deal with other products such as Windows Server AppFabric  or WSUS , Windows Server Update Services . It's an old-style pure server, on-premises, physical.

    I use patch management, such as the update services. We do have it, but it's not me who's taking care of it.

    I see lots of new features that Microsoft brings into Windows Server 2025. I understand it's not ready for a general release yet. It's definitely very interesting with the new features and focused a lot on the cloud part of it, so it's something to explore.

    I can't say which specific feature I'm most looking forward to seeing since I don't deal with cloud. I don't have it in my environment, but I'm trying to learn it. I'm keeping up with my reading about it, so once I have a better understanding, maybe we can try something.

    I am still a system administrator with TFI International.

    On a scale of 1-10, I rate Windows Server a 9.

    Which deployment model are you using for this solution?

    On-premises
    Jai Prakash Sharma

    Efficient Management Achieved with Internal Resources and Reliable Technical Support

    Reviewed on May 22, 2025
    Review provided by PeerSpot

    What is our primary use case?

    My purpose for using Windows Server  is mostly for Microsoft workloads, which includes ERP , NAV, NAVISION, and for 365 Dynamics, as we have recently migrated to 365 Dynamics from an on-prem Microsoft Dynamics  solution. We utilize Active Directory, Windows Server  for MS SQL  Server, and SharePoint , and we are already a customer for Azure  cloud as well.

    What is most valuable?

    From my personal perspective, the most beneficial functions and features of Windows Server are predominantly its services for Active Directory, as well as its support for SQL Server  and any .NET or ASP.NET  applications that we have hosted using the IIS  server.

    Windows Server helps with our data protection strategies through Microsoft security services. On top of Microsoft Server, we have to use certain third-party applications; while Microsoft server services provide good host-level security, external application level security often requires additional third-party solutions.

    What needs improvement?

    Regarding drawbacks of Windows Server, the solution can definitely be improved, as it is quite vulnerable since Windows is widely adopted in the industry, making it an easier target. We need to ensure that we have antivirus running; while Windows Defender antivirus has improved, it still lacks in areas such as behavioral analysis, and AI-based attacks are not very efficiently detected.

    We use third-party applications for app controls and manage Privileged Access Management  with third-party integration, even if we use the AD topology. We also rely on third-party solutions for multi-factor authentication.

    For how long have I used the solution?

    I have been working with Windows Server for quite a long time. My experience spans more than 35 years, and in this organization, I have been here for almost around 14 to 15 years.

    What was my experience with deployment of the solution?

    The installation of Windows Server is quite easy, but Windows Server tends to be a little resource-hungry, and customization from a server standpoint is limited, which is my perspective.

    What do I think about the stability of the solution?

    Regarding stability, the experience can depend on housekeeping practices. If maintenance is regular, I don't encounter many day-to-day challenges. However, if maintenance is neglected for an extended period, performance issues and contention may arise, but overall, it remains pretty controllable.

    What do I think about the scalability of the solution?

    In terms of scalability, Windows Server does have certain challenges; many tools are proprietary to Windows Server. For instance, it doesn't have a default load balancer, and although licensing models differ when using cluster service, scalability is not fundamentally a challenge. The cost of the operating system version can impose different challenges, though.

    How are customer service and support?

    The technical support from Microsoft is one of the best, though there can be challenges when it comes to priority zero or critical issues, where the queue can be longer.

    If I were to rate Microsoft support from one to ten, I would rate it around eight to eight plus.

    How would you rate customer service and support?

    Positive

    What was our ROI?

    Working with Windows Server does save me time and money. The return on investment is evident as having efficient resources to manage our infrastructure means we are less dependent on costly external support from Microsoft. An in-house team can manage things quite efficiently without needing additional assistance.

    In terms of ROI, it saves us roughly 10 to 20% in terms of time and resources.

    What's my experience with pricing, setup cost, and licensing?

    The cost associated with Windows Server—considering pricing, licensing, and setup—is expensive, no doubt.

    What other advice do I have?

    Maintenance of Windows Server varies by organization, but for us, it's not very difficult as we have in-house resources managing these tasks. However, it can become a bit tricky when we want to see a collated view of our security posture.

    Regarding AI integrations with Windows Server, Copilot adoption is progressing, though I have only experienced it on endpoints and not on the server side. We operate significant workloads on AI, but we consume those primarily on Linux rather than Windows Server.

    I don't have much experience regarding integration capabilities in Windows Server for AI workloads, so I may not be the right person to provide insights on that.

    Overall, I am quite happy with my experience using Windows Server. I don't have many constraints or concerns, so I would rate it eight out of ten.

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Gustavo Schleider

    Long-standing experience improves reliability and security, making it a trusted platform

    Reviewed on May 15, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I administer Windows Server . We have Windows 10  and are migrating to Windows 11  under my organization. The people who work with me are handling the migration right now.

    We have several servers, most of them Windows Server . We have a couple of Linux servers, but most of our servers are Windows Server. We maintain the normal infrastructure, including domain controller. We still have a file server and other specific servers. We have an Exchange Server that is only for hybrid purposes as we use Exchange Online . For specific tasks, we need a server to be managed. 

    What is most valuable?

    Several years of improvements have been made to the software itself. In the '90s, it was poorly reliable. Now it's very reliable; you can spin up a Windows Server box, and it will run without needing to reboot unless updating. It's quite secure, which wasn't the case previously. They improved security over the years. It's a standard, compatible and backwards compatible with several pieces of software, and it's a standard platform where you can find practically any server software that you need. For me, it's a standard platform right now. They gained the market over the years.

    What needs improvement?

    It's difficult to see improvements when using it daily. They improved compatibility with other platforms, such as Linux. One improvement I was thinking about some years ago was the ability to manage an on-premises server from Azure . Now, they have created Azure  Arc, and we are using it as a very good way of managing on-premises servers.

    What can be improved is on the Azure side. With Active Directory on the server side and Entra ID on the Azure side in our hybrid environment, we find issues with data syncing to Entra ID. In Entra ID, Microsoft omitted some parameters. In Active Directory, you can put an expiring date to an account, but you cannot do that in Entra ID. We have other means of doing that, but it's common to have consultants working for six months, requiring account expiration or renewal processes.

    The Entra ID Connect syncing tool could be improved. Though they moved the service to Azure and use an agent instead of having a dedicated server, it remains cumbersome to set up due to the differences between Entra ID and Active Directory.

    For how long have I used the solution?

    I have used Windows Server since Windows NT 3.1 in 1993.

    What do I think about the stability of the solution?

    I would rate stability as nine. I don't tend to rate ten because nothing is perfect.

    I support it myself and don't recall having any issues requiring Microsoft assistance for Windows Server. I usually solve issues myself. In the '90s, I was at Microsoft on an internship, receiving good training on the internals of Windows NT, which is the basis for the actual Windows Server. Though it has changed significantly, the inner workings remain generally the same.

    What do I think about the scalability of the solution?

    It's quite scalable. I would rate it nine because it's very scalable internally, and you can use federation to connect to other systems. During company fusions, it's straightforward to connect them if you understand the process. You can use external authentication features to authenticate with Facebook, Google, or Apple. It's quite flexible, scalable, and can manage a tremendous amount of users. My current company is small with approximately 2,600 users, but I've worked in companies with 20,000 to 100,000 users, and it scales beautifully without issues.

    How was the initial setup?

    The setup complexity depends on your training. You need to understand what you're doing. I've seen many people trying to set up Windows Server as if it were Windows desktop. They don't properly manage permissions or understand the difference between local permissions and domain permissions. If you are properly trained and understand how permissions work, then setting up Windows Server isn't problematic. The installation itself is simple, as they have improved it significantly. However, the challenge lies in knowing which services, roles, and features to add afterward. Training is essential for these aspects.

    What about the implementation team?

    I usually support it myself.

    What was our ROI?

    The return on investment is very good. You get a standard platform that is very secure and stable. The return on investment is very good.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is fair. There isn't much competition apart from Linux, which has support pricing rather than product pricing. Microsoft offers product pricing with licenses per processor and CAL licenses for accessing. The complexity of licensing can be difficult to understand for inexperienced users, but regarding pricing, there is no comparison.

    What other advice do I have?

    I would rate Windows Server at seven because while it's not overly difficult to understand, the experience level matters significantly. For me, having started in 1993 with Windows Server, I do it from memory. I know what to set up, what services need to be running, and how to harden it.

    I would recommend the product. Training is very important before implementation if you don't have previous experience, or alternatively, engage a consulting company that knows what they are doing for proper implementation. The overall rating for Windows Server is nine out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Microsoft Azure
    Azizul Haque

    User-friendly server enhances banking operations through robust virtualization

    Reviewed on May 02, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I am working in a bank, and we use Windows Server  for different purposes and services. Specifically, it is used for our banking system and banking software. We need to install software and databases on Windows Server .

    What is most valuable?

    Windows Server is user-friendly compared to other operating systems, like Linux. It offers virtualization techniques, such as Hyper-V , and other features that make it favorable. It is also user-friendly, which is beneficial for my organization as it simplifies processes.

    What needs improvement?

    One area that needs improvement is the protection against ransomware attacks. A mechanism similar to what Linux offers for preventing ransomware attacks would be beneficial.

    For how long have I used the solution?

    I have been working with Windows Server for at least ten years.

    What do I think about the stability of the solution?

    I would rate the stability of Windows Server as nine out of ten.

    What do I think about the scalability of the solution?

    I would also give a rating of nine out of ten for scalability and its ability to expand.

    How are customer service and support?

    I would rate the technical support from Microsoft an eight out of ten. The response time is one area that could use improvement.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial setup of Windows Server is very simple. While it used to be complex, it has become more straightforward and easier over time.

    What's my experience with pricing, setup cost, and licensing?

    The pricing for Windows Server is moderately high, and with time, the price is increasing. It is suggested that Microsoft focuses on the pricing issue.

    Which other solutions did I evaluate?

    Windows Server's main competitor is Linux, but it is not as user-friendly, making Windows Server a preferred choice in my country.

    What other advice do I have?

    I would give Windows Server an overall rating of eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Mustafa Farhat

    Manage IT infrastructure securely and effectively with intuitive management features

    Reviewed on Apr 24, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I use Windows Server  to run our IT infrastructure. Almost everything is located on Windows Server , including our SQL database, our system, web server, and virtualization via Hyper-V .

    What is most valuable?

    Windows Server offers easy-to-use features, support, a web interface with a Windows interface, and security. The security features, such as Windows Defender, are excellent. I can manage the firewalls on the server easily, open or close ports to manage security traffic, and use encryption on the hard disk to keep data secure.

    For how long have I used the solution?

    I have been using Windows Server for about twenty-five years, starting with Windows 2003.

    What do I think about the stability of the solution?

    I would rate the stability of Windows Server between eight and nine. Sometimes Microsoft publishes updates that aren't compatible with the system, which they then pull back. In general, stability is between eight and nine.

    What do I think about the scalability of the solution?

    I rate the scalability of Windows Server as eight out of ten. There are some systems that do not work on Windows or are complicated to deploy on Windows, especially those that operate in a Linux environment and cannot be installed on Windows.

    How are customer service and support?

    I had one experience with Microsoft's technical support, which was very good. I would rate them nine or ten. I don't have extensive experience with IT support because I don't often need it. Most issues can be resolved through public websites and forums. When I had an issue with Hyper-V , the support was excellent.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I use Red Hat Linux alongside Windows Server.

    How was the initial setup?

    The installation is straightforward and easy to install.

    What about the implementation team?

    My colleagues and I deploy the servers ourselves.

    What was our ROI?

    I get the features I am looking for from the price, despite it being a bit expensive. I benefit from Microsoft 365, Azure , and the features and services I need.

    What's my experience with pricing, setup cost, and licensing?

    The price of Microsoft products has become expensive over the last two years.

    What other advice do I have?

    I recommend Windows Server to others. Based on my experience, I rate this solution as a ten out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    View all reviews